> For the complete documentation index, see [llms.txt](https://nightowl131.gitbook.io/aapg/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://nightowl131.gitbook.io/aapg/manual-static-analysis/analyze-androidmanifest.xml.md).

# 1.3 Analyze AndroidManifest.xml

## 1.3.1 RETRIEVE MANIFEST ONLY

**(already covered if you have properly decompiled the app)**

```
aapt dump app_name.apk AndroidManifest.xml > manifest.txt
```

*or*

```
aapt l -a app_name.apk > manifest.txt
```

*within drozer-shell ("dr>"):*

```
run app.package.manifest com.x.x.x
```

### CREATE BACKUP

*full backup:*

```
adb backup -all -apk -shared 
```

*single app backup:*

```
adb backup com.x.x.x
```

*decode unencrypted backup:*

```
xxd backup.ab
```

> *(for the command above)* check if encrypted: if you see "**none**" --> not encrypted

```
dd if=all-data.ab bs=24 skip=1
```

*or*

```
openssl zlib -d > all-data.tar
```

*extract it:*

```
tar xvf all-data.tar
```

## 1.3.2 INFO

*APPLICATION*

{% hint style="info" %}

* Version & Requirements:
  * **\<uses-sdk android:minSdkVersion="23" android:targetSdkVersion="28"/>**&#x20;
* Existing activities:
  * **\<activity android:name="com.x.x.x....MainActivity" ... >**&#x20;
* Used Services:
  * **\<service android:name="com.x.x.x....SampleService" ... >**&#x20;
  * find class which interacts with external resources and databases
    {% endhint %}

*PERMISSIONS*

{% hint style="info" %}
**\<uses-permission android:name="android.permission.WRITE\_EXTERNAL\_STORAGE"/>**
{% endhint %}

*DEBUG APPLICATION*

{% hint style="info" %}
Debugging running apps or processes with [GDB](https://source.android.com/devices/tech/debug/gdb)
{% endhint %}

## 1.3.3 THINGS TO REPORT

{% hint style="danger" %}

* Wrong version/requirements specified
* **android:allowBackup = TRUE**
* **android:debuggable = TRUE**
* **andorid:exported= TRUE** or not set at all (within <*provider*>-Tag) --> allows external app to access data
* **android.permission.WRITE\_EXTERNAL\_STORAGE** / **READ\_EXTERNAL\_STORAGE** (ONLY IF sensitive data was stored/read externally)
* improper use of permissions:
  * e.g. the app opens a website in external browser (not in-app), however requires "*android.permission.INTERNET*" --> false usage of permissions (over-privileged)
  * "android:protectionLevel" was not set properly \
    (**\<permission android:name="my\_custom\_permission\_name" android:protectionLevel="signature"/>**)
  * missing **android:permission** \
    (permission tags limit exposure to other apps)
    {% endhint %}

## 1.3.4 MORE DETAILS

{% hint style="info" %}

* [Application elements](https://developer.android.com/guide/topics/manifest/application-element)&#x20;
* [Security guidelines for AndroidManifest](https://pentestlab.blog/2017/01/24/security-guidelines-for-android-manifest-files/)&#x20;
* [Android Platform Releases](https://developer.android.com/studio/releases/platforms)
  {% endhint %}
